On TechRepublic: Linux desktops have tanked: Get over it
BNET Business Network:
BNET
TechRepublic
ZDNet

May 12th, 2009

Microsoft plugs 14 PowerPoint security holes

Posted by Ryan Naraine @ 10:38 am

Categories: Anti Virus, Arbitrary Code Execution, Browsers, Complex Attacks, Data theft, Denial of Service (DoS), Exploit code, Hackers, Malware, Microsoft, Patch Watch, Responsible disclosure, Reverse Engineering

Tags: Security, Vulnerability, Microsoft PowerPoint, Microsoft Corp., Microsoft Office, Office Suites, Software, Ryan Naraine

Microsoft has slapped a massive band-aid on its PowerPoint presentation software to cover at least 14 documented security vulnerabilities.

The MS09-017 update, rated “critical,” includes a fix for a known code execution flaw that was used to launch targeted exploits via rigged PowerPoint files.

[ SEE: Patch Tuesday: Fix coming for PowerPoint zero-day ]

From the bulletin:

The security update addresses the vulnerabilities by modifying the way that PowerPoint handles conditions that could cause memory corruption when opening specially crafted PowerPoint files. This update also addresses the vulnerabilities by preventing Microsoft Office PowerPoint 2000 and Microsoft Office PowerPoint 2002 from opening PowerPoint 4.0 native file formats.

Some of the issues affect Office for Mac but patches are not yet available for those users:

The updates for Office for Mac and Microsoft Works 8.5 and 9.0 users are still in development. Microsoft plans to issue updates for these software when testing is complete and we can ensure high quality. We are releasing this security update on an incremental basis because of active targeted exploitation toward Windows platform users.

Three of the 14 issues are described as “legacy file format vulnerabilities” that introduce code execution risk via specially crafted PowerPoint files.  They could be exploited via PowerPoint files in e-mail attachments, or hosted on a specially crafted or compromised Web site.

Microsoft’s Johnathan Ness explains:

We are addressing a number of PowerPoint converter cases by removing support for the format (PP40). Others were addressed by back-porting the latest Office 2003 SP3 converter code down-level to Office XP and Office 2000. For example, PP7X32.DLL has gone through extensive changes, addressing the externally-reported vulnerabilities listed in the bulletin but also introducing substantial hardening to the parsing engine. We hope that by doing this comprehensive update and by proactively addressing security vulnerabilities, we reduce the risk and help protect our customers from future vulnerabilities.

* Image source: cogdogblog’s photostream (Creative Commons 2.0)

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 25 Talkback(s)
OpenOffice Impress
As I understand it (and I don't claim omniscience) OpenOffice's Impress, which handles powerpoint files, is safe - or is that only if you're running it on Linux? --Anna... (Read the rest)
Posted by: maggietoo9 Posted on: 05/14/09 You are currently: a Guest | | Terms of Use
PP Viewer?  wkulecz | 05/12/09
No, the viewer  No_Ax_to_Grind | 05/12/09
Actually...  iTeaBoy | 05/12/09
Not applicable...  No_Ax_to_Grind | 05/12/09
Yes and in the Affected Software table...  iTeaBoy | 05/13/09
Sorry but you are wrong again.  No_Ax_to_Grind | 05/13/09
Your credibility is dubious...  SpikeyMike | 05/13/09
That's because I'm an idiot  Donald_Rupert | 05/13/09
The "Not Applicable"  oskiller@... | 05/14/09
But, was this in your PowerPoint book, NoAxe?  nizuse | 05/12/09
Yes it was  No_Ax_to_Grind | 05/13/09
Then give the title,  nizuse | 05/13/09
You know how to gert it, its simple  No_Ax_to_Grind | 05/13/09
Be a man and show us the title.  nizuse | 05/13/09
Here's the book I wrote  Donald_Rupert | 05/13/09
Here's the other book I wrote  Donald_Rupert | 05/13/09
Vulnerabilities and Exploits 101  iTeaBoy | 05/13/09
Can you read?  No_Ax_to_Grind | 05/13/09
Yes. Can you follow simple step by step instructions?  iTeaBoy | 05/14/09
Can't Install the Patch  dl@... | 05/13/09
I have a solution for you. Call NoAxe  nizuse | 05/13/09
None for Macintosh?  phatkat | 05/13/09
Not Applicable  kfan | 05/13/09
No_Ax and kfan - You are VERY WRONG!!  iTeaBoy | 05/14/09
OpenOffice Impress  maggietoo9 | 05/14/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here